Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

I would like to install 2 WSUS servers in Network-A which is connected to the internet and download updates to both servers separately.

From those servers I’d like to check the hash/checksum of the files (compare it) to see if there’s any data manipulation before moving them to my internal WSUS.

It's really totally unnecessary because it is architecturally impossible for WSUS to download a file that does not match the hash/checksum of the same file on any of the other gazillion WSUS servers around the globe.

WSUS has built-in hash/checksum checking, and in fact, will not even allow the file to be written to the ~\Content folder if the hash/checksum (SHA-1 hashes are used with WSUS) fails the value coded into the update metadata.

Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

I would like to install 2 WSUS servers in Network-A which is connected to the internet and download updates to both servers separately.

From those servers I’d like to check the hash/checksum of the files (compare it) to see if there’s any data manipulation before moving them to my internal WSUS.

It's really totally unnecessary because it is architecturally impossible for WSUS to download a file that does not match the hash/checksum of the same file on any of the other gazillion WSUS servers around the globe.

WSUS has built-in hash/checksum checking, and in fact, will not even allow the file to be written to the ~\Content folder if the hash/checksum (SHA-1 hashes are used with WSUS) fails the value coded into the update metadata.